Description
Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share, Print and PDF Products for WooCommerce: from n/a through <= 3.1.2.
Published: 2025-12-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the plugin contains a missing authorization check that allows unauthenticated or improperly authorized users to perform privileged operations. Because the access control security levels are incorrectly configured, an attacker could exploit the flaw to access or manipulate features that should be restricted, such as generating shared PDFs or printing options. This insufficient access control (CWE-862) can compromise both the confidentiality of documents and the integrity of the printing process for users who should not have those capabilities.

Affected Systems

The weakness affects the XforWooCommerce Share, Print and PDF Products for WooCommerce plugin in all releases up to and including version 3.1.2. The issue is present in every iteration from the initial release through 3.1.2, meaning any site still running those versions is exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of <1% reflects the probability of exploitation is currently low, and it is not listed in the CISA KEV catalog. Attackers can reach the flaw over the web interface, so the vulnerability is potentially remotely exploitable. Because it is an access control issue, any user who can interact with the plugin’s features and who is not properly authorized could leverage the flaw. The confidentiality impact inferred from the data is that an attacker could view or obtain shared PDFs or other documents that should be protected.

Generated by OpenCVE AI on April 29, 2026 at 22:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Share, Print and PDF Products for WooCommerce plugin to a version that contains the access‑control fix.
  • Verify that all user roles interacting with the plugin have the appropriate permissions and that no role possesses unintended privileges.
  • Configure the website’s security settings to restrict access to the plugin’s functionality, ensuring that only authorized staff can generate PDFs or print documents.

Generated by OpenCVE AI on April 29, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Xforwoocommerce
Xforwoocommerce share, Print And Pdf Products
Vendors & Products Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Xforwoocommerce
Xforwoocommerce share, Print And Pdf Products

Tue, 30 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share, Print and PDF Products for WooCommerce: from n/a through <= 3.1.2.
Title WordPress Share, Print and PDF Products for WooCommerce plugin <= 3.1.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Woocommerce Woocommerce
Wordpress Wordpress
Xforwoocommerce Share, Print And Pdf Products
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:33.764Z

Reserved: 2025-12-29T11:18:04.294Z

Link: CVE-2025-68993

cve-icon Vulnrichment

Updated: 2025-12-30T15:49:42.027Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:15:58.043

Modified: 2026-04-27T19:16:40.443

Link: CVE-2025-68993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:15:16Z

Weaknesses